Linux: Detect Python .pth Path Configuration File Creation in site-packages

Alerts on creation of Python .pth files in /lib/python3.X/site-packages on Linux, which can trigger code at Python startup.

FreeReviewedSigma · Medium · v5
Product
linux
Category
file_event
Author
Andreas Braathen (mnemonic.io) (SigmaHQ), DRL 1.1
Published
2024-04-25
Updated
2026-07-31
title: "Linux: Detect Python .pth Path Configuration File Creation in site-packages"
id: 9cb80d04-3c42-459c-a490-ab3867249b27
related:
  - id: e3652ba3-0ad8-4010-a957-b7ba369e7bac
    type: similar
  - id: 4f394635-13ef-4599-b677-3353e0f84f55
    type: similar
  - id: fb96c26c-9f85-4ae7-af0d-ed1ed1f1f5ce
    type: derived
status: test
description: This rule flags creation of Python path configuration files (.pth) under Python’s site-packages directories on Linux. Attackers can abuse .pth files because their contents are evaluated during Python startup (v3.5+), enabling code execution or persistence without requiring the script to explicitly import the referenced module. It relies on file creation telemetry that includes the created filename and full path, matching for *.pth files within /lib/pythonX.Y/site-packages.
references:
  - https://www.volexity.com/blog/2024/04/12/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in-globalprotect-cve-2024-3400/
  - https://www.virustotal.com/gui/file/3de2a4392b8715bad070b2ae12243f166ead37830f7c6d24e778985927f9caac
  - https://docs.python.org/3/library/site.html
  - https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/linux/file/file_event/file_event_lnx_python_path_configuration_files.yml
author: Andreas Braathen (mnemonic.io), Huntrule Team
date: 2024-04-25
tags:
  - attack.execution
  - attack.t1059.006
  - detection.threat-hunting
logsource:
  product: linux
  category: file_event
detection:
  selection:
    TargetFilename|re: (?i)/lib/python3\.([5-9]|[0-9]{2})/site-packages/
    TargetFilename|endswith: .pth
  condition: selection
falsepositives:
  - Although .pth files are discouraged due to potential security implications, these are legitimate files by specification.
level: medium
license: DRL-1.1